PT-2013-3871 · Digium · Asterisk

Matt Jordan

+2

·

Published

2013-03-29

·

Updated

2013-04-02

·

CVE-2013-2685

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Asterisk Open Source versions prior to 11.2.2
Description The issue is related to a stack-based buffer overflow in the res/res format attr h264.c file, which allows remote attackers to execute arbitrary code via a long sprop-parameter-sets H.264 media attribute in a SIP Session Description Protocol (SDP) header.
Recommendations For versions prior to 11.2.2, update to version 11.2.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the res/res format attr h264.c file or limiting the length of the sprop-parameter-sets H.264 media attribute in SIP SDP headers to minimize the risk of exploitation.

Fix

RCE

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-2685

Affected Products

Asterisk